Incident Response Retainer

We can help your company establish terms and conditions for incident response services. We can help you do this before a cyber security incident is suspected. Our experts will be able to help your business.

Be Prepared for the Unexpected

Cyber attacks are becoming increasingly sophisticated and common, and no organisation is immune. If you are hit by a cyber attack, it is important to have a plan in place to respond quickly and effectively. An incident response retainer service can help your business do just that.

This service is a pre-arranged agreement between an organisation and a security services provider to provide incident response services in the event of a cyber attack. The retainer service typically includes a team of experienced incident response professionals who are available 24/7 to help you to contain, remove, and recover from an attack.

Web application penetration testing targets the web apps and APIs that a business will rely on to enable user functionality and access data. The objective is finding and demonstrating security flaws like cross-site scripting, SQL injection, remote code execution, account takeover flaws, and business logic flaws.

Testers perform activities such as injecting malicious inputs, analyzing error messages, reverse engineering session cookies and access tokens, mapping out functionality and workflows, attempting authentication bypass, and aggressively manipulating parameters and scripts to uncover holes in validation, authentication, and access control schemes.

The output of web app pen testing is typically a risk-rated set of findings, proof-of-concept exploits, and remediation guidance. Depending on scope agreed upon, this may focus on custom corporate apps, commercial SaaS apps, APIs, mobile apps, thick client apps, and even IoT embedded web interfaces. The risk rating quantifies potential impact. For example, an XSS flaw enabling account takeover on a sensitive admin portal would be critical, while XSS on a marketing site may be low or informational risk.

What our Clients Say About Us

You did tell me that no solution would give us 100% protection but knowing that we have your team carrying out regular reviews and available should we ever need them, give me restful night.
Mark Ficher
Operations Director
I was been told that becoming Cyber Essentials certified was a complex and expensive. Your team made the whole process seam so simple for me. I am not so sure my IT Support company felt the same. Thank you for a first class service.
Tim Smith
Director
My and team and I thought our company was too small to ever be a target of a cyber attack but we were clearly wrong! Thank you for helping us and saving our business.
Diana Burns
Finance